[Full-disclosure] cpanel exploit

Todd Burroughs todd at parsec.net
Fri Sep 29 11:56:20 BST 2006


Anyone have any info on this cpanel exploit.   I have a friend who found it
pretty open to full user level acess, but not root.

I'm curious to know what the hole is/was.

http://www.thewhir.com/marketwatch/092706_Web_Hosts_Hit_by_Hackers.cfm

http://news.netcraft.com/archives/2006/09/23/hostgator_cpanel_security_hole_exploited_in_mass_hack.html

Todd

---
The Internet has given us unprecedented opportunity to communicate and
share on a global scale without borders; fight to keep it that way.

Jesus died for your sins, make it worth his time.




Full-Disclosure is hosted and sponsored by Secunia.